Critical 9.6 Unfixed
2026-04-08≤ 3.2
CVE-2026-39640
Minimum safe version
3.1
Update to 3.1 or later to address 8 fixable vulnerabilities
CVE-2026-39640
WordPress Theme Editor Plugin <= 3.0 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2022-2440
CVE-2023-6091
Theme Editor < 2.2 - Multiple Vulnerabilities
Theme Editor <= 2.1 - Cross-Site Request Forgery
WordPress Theme Editor plugin <= 2.1 - Multiple vulnerabilities
WordPress Theme Editor plugin <= 2.5 - Multiple Authenticated Arbitrary File Download vulnerabilities
CVE-2021-24154